Last Updated: 9th April, 2019
1. Our Privacy Statement
We are Xxtra Research Pty Ltd ABN 19 125 415 385 the operators of Airtime Surveys, an online community and surveys platform from Australia. Xxtra Research Pty Ltd from here on in will be referred to as our business name, Xtra Insights.
We consider your privacy to be important and we take our responsibility to protect it seriously. We understand that you are concerned about your privacy, along with the confidentiality and security of any personal information that you provide to us.
2.Who are you?
How we process your personal data will depend upon how you use our services.
You may be an Admin Account Holder – You hold an Admin account for an Airtime Surveys Community and you either directly create surveys or you are monitoring surveys, feedback, memberships or results within your Admin Account. That means you’re both a “data subject” for your own data that you provide to us and a “data controller” for participants’ data that we process on your instruction.
You may be a Member Account Holder – You have received an invitation to and are a member of an Airtime Surveys Community or multiple communities and you respond to surveys, forms or applications received through your account. You are a “data subject” as you are providing your personal data to us for processing.
You may be a visitor to our website – You don’t have a Member Account or Admin Account, however you have landed on our website.
We act as both a “data controller” (when we collect your personal data ourselves, for example when you register a Member Account with us) and as a “data processor” (when we collect information on behalf of an Admin Account Holder, for example subject to a survey on the Airtime Surveys platform). Where you are completing surveys, forms or applications received through your account, the Admin Account Holder that has created the relevant survey, form or application will be the data controller.
3.Collection of information
We collect information about Admin Account Holders, Member Account Holders and visitors for different reasons.
Where you are a visitor to our website, we will only collect personal data about you where you have either consented to our collection of your personal data, or it is in our legitimate interests to do so.
If you are an Admin Account Holder or a Member Account Holder we will collect personal data about you where you have provided your express consent, to fulfil our contractual responsibility to deliver our services to you or to pursue our legitimate interests.
By accessing and using our services you are explicitly consenting to the collection and use of your personal data in accordance with the terms of this policy. By registering as an Admin Account Holder or Member Account Holder, you are consenting to the collection and use of your personal data in accordance with this policy. You may withdraw your consent to our collection and use of your personal data at any time by ceasing to use our services and notifying us that you have withdrawn your consent to the processing of your personal data.
Examples of where we collect personal data in our legitimate interests include where we are collecting your personal data to improve our service offering, or to develop new products and services.
4.Information we collect
We collect different types of personal data about you as you use our services. To make things easy, we have set out in the table below the type of information we collect and the purpose for which it is collected.
Nature of Information Collected
Example and Purpose
We collect this information when you set up an account with us as either a Member Account Holder or Admin Account Holder.
Age, gender, residential address and other contact details.
We collect this so that we can provide Admin Account Holders with information as to the nature and demographic of people and their opinions, for example, as it relates to content such as genres of music, songs, advertisements, radio personalities and competitions.
Social Media Information
Information that you choose to make available to us (for example the profile information on your Facebook page).
If you use Facebook or another social media platform to create or log into an account, we will collect information from your Facebook or relevant social media profile. We will only collect the information that you specifically provide to us.
Additional User Information
Your communications and feedback for the purposes of improving our services.
We collect information that you provide to us when you answer emails or surveys which we have conducted.
Contests and Promotions
We may collect your name, address, telephone number and other information that you have provided to us.
It is necessary for us to collect this information when you voluntarily participate in contests and special promotions we run.
Computer and Mobile Device Information
We access information from Microsoft and Google about the device and applications you use to access our services. Device data mainly means your operating system version, device type and browser version. We also access information about what Internet Service Providers you may have used to access our services.
This information provides us with a more detailed picture of who you are, how you access and use our services and is often critical information when diagnosing issues with our services.
Information from Cookies and similar technologies
We use first-party cookies in our Airtime Services for security to identify your account and track your movement throughout the websites. The cookies expire (and therefore are automatically deleted) when you end your browsing session (such as when you log out or close the browser).
This information helps us with security and provides us with more detail on how you access and use our services. Cookies enable us to gather metrics about your experience and to tailor advertising to you.
Information from Third Parties
If you use an Airtime service from an external source (such as a link on another website or in an email), we record information about the source that referred you to us. We also use Google Analytics Demographics and Interest Reporting. All Google Analytics information is completely anonymised and can only be viewed by us in aggregate.
This information gives us a broad snapshot of the nature and use of our services relating to visitor age, gender and interests on an anonymous and aggregate level. This will help us to give you a better experience while visiting our sites. It cannot be used to personally identify you.
5.How and why do we collect and process information?
We process data that we have collected about you in accordance with this policy in different ways. How we process your data will largely depend on whether you are using our services as a visitor, or as a Member Account Holder or an Admin Account Holder.
There is a lot of information in this section, so to make things easier for you, we have broken down the categories of users of our services. Each section sets out how and why information is collected about our different user groups.
Where you have provided it to us and consented to our processing of your personal data, we will collect your contact information, which may include your name, email address, telephone number or any other information that you provide us in an enquiry, online form or otherwise. We use this information to get in contact with you to respond to queries and provide you with information. If you have agreed to it, we may also send you direct marketing and promotion information. If we have sent you marketing and promotional information directly, you will be able to opt-out at any time.
We may also collect your Computer and Mobile Device Information and Information from Cookies and similar technologies. We collect this information to:
- allow us to improve our services;
- allow us to improve our security and prevent illegal (including fraud), abusive and detrimental activity;
- helps us determine the nature in which you have used our services;
- allow us to assess the success of our advertising and emailing campaigns;
- troubleshoot problems with our services and make improvements;
- track the success of our integrations and referral processes (for example, if you were directed to our website by another website).
Please note that where we have collected personal data about you, we may be required to disclose that personal data for the purposes of complying with a relevant law or court order.
5.2Member Account Holders and Admin Account Holders
As a Member Account Holder or Admin Account Holder we collect the following types of information about you to fulfil our contractual obligations to deliver our services to you, and in our legitimate interests:
- Account Information
- Profile Information
- Social Media Information
- Additional User Information
- Computer and Mobile Device Information
- Information from Cookies and similar technologies
We use your Account Information, Profile Information and Additional Information to respond to your inquiries, provide surveys to members of your community, send information as part of our services, identify information that you have provided in response to a survey and, provided you do not opt-out, to send you marketing and promotional information. We need to use your account data to run your account, provide you with our services, bill you for our services (if Admin Account Holder), provide you with customer support, and contact you about our services and your account. Please note that you can opt out of direct marketing and promotional communications at any time by unsubscribing through the links in any communications you receive or otherwise changing your account settings.
We will use Computer and Mobile Device Information and Information from Cookies or similar technology to:
- identify your logged-in account as you navigate through our sites;
- provide a level of resilience against network connection problems;
- ensure our services are fully functional and operating at an optimal performance level;
- ensure our surveys operate appropriately;
- allow us to measure the performance of email messaging and improve email messaging services;
- collect data regarding completion rates of surveys;
- provide us with information regarding the nature of surveys being created using our services;
- identify and fix functionality errors;
- monitor illegal, abusive or undesirable behaviour;
- to track the success of our integrations and referral processes from third parties;
- enforce our agreements and comply with other lawful requirements.
Admin Account Holders are also provided with a degree of control over how we process data collected on their behalf. Where you have responded to a survey as a Member Account Holder, we aggregate response data and activity in order to identify trends, recommend services and devise new products and services.
You can object to any such use of your data set out above. However, we may not have the ability to fully and properly provide our services to you if you do not want us to collect or use the above data.
Please note that at no time will we ever sell to a third party (being a party other than the Admin Account Holder) survey response data.
6. Overseas Data Transfers
To store your personal data, provide customer support, perform back office functions, fraud prevention tasks or provide services to you we may need to allow our staff, suppliers and service partners (who may be located or whose resources may be located in a country other than your country of residence) to access de-identified personal data that you have supplied. The parties to which we may allow access to such information include:
- Amazon Web Services
We have implemented security measures to protect the security of your personal data. However, as with any transfer of data, there are still risks of data breaches. There may be instances where your personal data is transferred to third party countries and international organizations, which have not been the subject of an adequacy decision by the General Data Protection Regulation Commission. Such transfers are necessary in order for us to perform our contractual obligations and also to deliver the services.
By providing your personal data you are explicitly consenting to the international transfer and processing of such data in accordance with this policy, in full and informed knowledge of the risks associated with such transfers and processing.
You may withdraw your consent at any time by contacting us using the contact information contained in this policy or by unsubscribing. However, this may affect or limit your ability to use our services.
In all other circumstances we will only disclose personal data to a third party country recipient or international organization if the disclosure of the information is required or authorized by or under a law of the EU, an Australian law, other applicable law or a court/tribunal order.
7. Information you share
Many of our services let you share information with others. We strongly recommend never sharing your password or access with any other person. Where you are an Admin Account Holder, remember, you hold the keys to a number of your data subjects’ personal data. Therefore, you also have a responsibility to them.
Our services provide you with different options on sharing and deleting your content but we cannot delete data that you have shared outside our services.
We consider data security incredibly important no matter which country you are located in. We have a comprehensive security system in place to protect your information. We use administrative, technical and physical safe guards to ensure your data is stored and used securely.
All our staff are trained in appropriate administrative steps to reduce risk of loss, misuse, unauthorized access, disclosure and alteration of your data.
We use secure server software to encrypt Personal Information. We use third party companies to store behavioral information, but these are anonymized and aggregated and we only partner with third parties that meet and commit to our security standards.
Our onsite premises are secured to ensure no loss of hardware which stores personal data.
Our Data Protection Officer (who is identified in the contact information below) regularly reviews security and privacy practices to ensure our systems are up to scratch. While we cannot guarantee that loss, misuse or alteration of data will not occur, we use reasonable efforts to prevent this.
It is also important for you to guard against unauthorized access to your personal data by maintaining strong passwords and protecting against the unauthorized use of your own computer or device.
9. Our Service Partners
We are sometimes required to engage third parties in order to provide you with the full scope of our services. We utilise third parties to:
- facilitate the sending of emails to Member Account Holders;
- track and report on marketing metrics;
- provide payment facilities;
- support you in your use of our services.
All third parties that are engaged are required to comply with the same data security and privacy standards that we impose, and that are otherwise imposed by law.
10. Data Retention
We keep a record of your data for as long as necessary to provide our services to you.
If you are an Admin Account Holder, at the end of our contract with you, we remove your access to Airtime Surveys within 5 business days, but we keep your details on record for a minimum of 30 days, or as required by local laws.
If you are a Member Account Holder, we will retain any personal data provided by you in response to a survey for as long as directed by an Admin Account Holder. You should enquire from your Admin Account Holder as to how long they will be directing us to retain your data.
We also provide functionality within your account allowing you to amend, update or delete certain personal data.
If your account is cancelled for any reason, for example you unsubscribe or can no longer be contacted, we will use anonymization and pseudonymization techniques to remove any personal data which might be used to identify you.
11. Safety of Minors
We do not offer our services to any persons who are minors, being persons under the age of 16, or the age designated for minors as determined by the laws of the specific jurisdiction in which our services are being accessed, without the specific consent of the minor’s legal parent or guardian.
If we become aware that we have collected personal data relating to a person who is a minor without the informed legal consent of the minor ’s legal parent or guardian, we will delete that information without notice.
In the event that we are required to make changes to this policy we will identify the changes that have been made on our website. We will notify you directly, either through your account or by using contact details that you have provided to us, where the amendment to our policy will result in a substantial change to the way in which we process your personal data.
13. Direct marketing campaigns
If we have contacted you directly with marketing and promotion material, you will be provided with functionality allowing you to opt-out of such direct marketing contact.
14. Your rights
We provide you with a number of rights in regard to the personal data that we process. These rights include:
- access upon request to your personal data;
- the right to withdraw consent – even after it has been provided, you may withdraw your consent to our processing of your data at any time by contacting us;
- the ability to restrict the way we use your data. You may request restriction on processing for specific actions that we are undertaking, whilst not restricting our processing of other kinds of your data;
- the right to correct your data – if you feel that the data we are storing about you is incorrect, please contact us to notify us of the error, or alternatively amend your data through your account;
- the right to obtain a copy of your data – where possible and feasible to do so, we are happy to provide you with a copy of the data that we hold about you, in an electronic format that you may provide to other processors or controllers;
- the right to be forgotten – we will erase your data within 1 month upon the termination of your contract (if Admin Account Holder) or upon request. You may also contact us directly requesting that we delete any of your personal data that we are processing;
- the right to object to processing – even after you have provided your consent, you may object to our use of your personal data for certain processes.
If you are a Member Account Holder and you have responded to a survey, form or questionnaire, you may need to reach out to the Admin Account Holder (who will be the data controller) to organise the access to, correction, restriction or erasure of your personal data. We will provide you with all reasonable assistance in this regard.
If you are a visitor to our website and want to exercise any of the above rights, please contact us directly using the contact information detailed below.
We will respond to all requests to exercise the above rights within a reasonable time (and in all cases within 1 month of receiving a request).
15. Contact Details
Xxtra Research Pty Ltd, operating as Xtra Insights, is responsible for the use of your data and for responding to any requests related to your personal data. Contact details for Xtra Insights are as follows:
Phone: +61 7 3314 6796
Address: PO Box 40, Lutwyche, 4030, QLD, Australia.
Xtra Insights has appointed a Data Protection Officer. Contact details for the Data Protection Officer are as follows:
Phone: +61 7 3314 6796
Address: PO Box 40, Lutwyche, 4030, QLD, Australia.
If you are based in the European Union you may contact our European Representative, the details of which are:
ON AIR Digital Rainer Eichhorn GmbH
Phone: +49 30 8595590
Address: Wilhelm-Kabus-Str. 70 | Haus 34, 10829 Berlin, Germany.
If you have any questions or complaints, please contact us at any time using the above details. We will endeavour to respond within 1 business day.
Where you are a resident of the European Union, you may also wish to contact your local data protection supervisory authority.